Skip to main content
technology Start a Project

Published note

Building a Compliance Command Centre for a Global Trading Floor

September 3, 2026

Line art of a three-screen trading control room console with a compliance shield, titled Compliance command centre for a global trading floor, on the greenstar technology dark brand background

Over three years, greenstar technology designed, built and now operates an enterprise telecommunications and compliance intelligence platform for the trader voice and operations compliance function of a global commodities trading enterprise — a single source of truth for every call recorded, every message captured and every regulatory obligation met, across three continents.

ClientGlobal commodities trading enterprise (name withheld)EngagementDiscovery → build → run, 3 years and countingCoverageEMEA / AMER / APAC
90,000+
trading-floor calls processed daily
12
external platforms integrated and orchestrated
40+
scheduled intelligence jobs running around the clock
30+
dedicated dashboard modules across three regions

Tens of thousands of calls a day. Zero tolerance for gaps.

A trading floor generates tens of thousands of calls daily across a complex web of voice, SMS and chat platforms. Regulators expect every one of them to be recorded, retained, retrievable and linked to a regulated identity.

Before this platform, proving that meant manual reconciliation across five separate vendor portals, siloed dashboards maintained by different teams, missed alerts, and a compliance exposure nobody could size with confidence. Recording lapses surfaced days late, if at all. Device installations were tracked in spreadsheets. Incident context lived in another system entirely.

Our business analysts embedded with the client’s trader voice and operations compliance teams to map that landscape end to end: every recording platform, every retention obligation, every joiner-mover-leaver process, every point where a call could silently fail to be captured. That analysis became the blueprint for a single platform — and the operating model the client’s global teams still run on today.

One platform orchestrating twelve

The platform doesn’t replace the estate — it masters it. Every critical system feeds one intelligence layer: call metadata polled every fifteen minutes, identity data refreshed every five, webhook events signature-verified and captured in real time, and headless-browser extraction where a vendor offers no API at all.

Source system What the platform extracts Cadence
Cloud9 / Xhoot Call metadata, user groups, connection health, billing 15 min, 24/7
ASC Neo Recording audit logs, call exports, amendment tracking, voice insights via headless-browser extraction scheduled
Cohesity / Veritas Storage connector health, backup compliance, real-time alerting across all nodes continuous
Twilio Inbound and outbound call logs, caller IDs, service health, SMS delivery status scheduled
Dubber Interaction recordings and metadata with full lifecycle tracking scheduled
LeapXpert SMS and iMessage identity linking, user verification, export audit trails 5 min
SteelEye Recording-lapse reports, employee communications compliance daily
Arctera Chat reconciliation across nine sources: Bloomberg, Reuters, ICE, WebICE, Enmacc and more daily
ServiceNow Incidents, service tasks, change requests and ritual scheduling continuous
Microsoft Teams / ASC Joiners, movers and leavers tracking; mobile device management lifecycle scheduled
Secret Server Endpoint installation reporting, credential-protected device compliance scheduled
Loopmessage Webhook-driven iMessage capture: inbound, sent, failed, reactions, group events real time
0.22%
The reconciliation engine runs T+0, T+1 and T+2 strategies daily and flags discrepancies this small — finding 190 missing calls in a dataset of 90,000 — before a regulator or an audit ever could.

From reactive and fragmented to proactive and audit-ready

For trader voice operations

  • Real-time call intelligence — live volume monitoring with time-weighted health scoring that knows how many calls should have been processed by any point in the day.
  • One view, not five portals — multi-source aggregation replaced separate vendor dashboards and the swivel-chair workflow between them.
  • Automated reconciliation — daily T+0, T+1 and T+2 strategies with gap detection down to fractions of a percent.
  • Connector health at a glance — 0–100% health scores, consecutive-error detection and actionable recommendations before issues escalate.
  • Planned maintenance, planned for — outage and maintenance windows integrated directly into the monitoring view.

For operations compliance

  • Recording-lapse mastery — real-time lapse tracking across four recording estates, with joiners, movers and leavers handled automatically.
  • Chat reconciliation at scale — nine-source message verification spanning Bloomberg, Reuters, ICE and more.
  • Identity verification, live — regulated-user identities confirmed against the source of record in real time, with intelligent caching. No stale data.
  • Device compliance visibility — app installation status, device health and endpoint reporting in one place.
  • A complete audit trail — every action, status change and system event logged with full activity history for regulatory review.

Built to run unattended, at trading-floor pace

Behind every dashboard panel sits an orchestration engine of more than forty scheduled jobs and 130+ data collections — engineered for the failure modes that actually happen in production, not the ones that demo well.

Concurrency
Database-backed execution locks
No duplicate runs, no race conditions, no double-counting — even with multiple cloud app-service instances scheduling the same jobs.
Signal
Smart alert suppression
Notifications fire only on genuine status transitions, not noise. Operations teams trust the alerts because there is no alert fatigue to tune out.
Scale
Serverless offload
Large reconciliation workloads shift to serverless functions on demand, keeping the core application responsive during the heaviest daily runs.
Resilience
Adaptive API throttling
Rate-limit awareness across all twelve integrations, with automatic retry and backfill logic when an upstream platform degrades.
Integrity
Verified webhooks, atomic writes
HMAC SHA-256 signature validation on every inbound event, and database transactions ensuring atomic writes across complex multi-document operations.
Security
Secure by design, not bolt-on
JWT authentication with granular role-based access, API-key lifecycle management with proactive expiry warnings, credential masking outside production, and zero hardcoded secrets.
Node.js · TypeScript · React 18 · Redux · MongoDB · Azure App Service · Azure Functions · ApexCharts

Analysis first. Then software. Then a running service.

This wasn’t a build-and-hand-over project. We ran the full lifecycle: business analysis alongside compliance officers to turn regulatory obligations into testable reconciliation rules; iterative delivery with the trading-floor teams who would live in the product; and an operating cadence that has kept the platform evolving through hundreds of releases over three years.

Today the platform runs as a service for the client’s global teams across EMEA, AMER and APAC — monitored, maintained and continuously extended as new communication channels, vendors and regulations arrive. When the estate changes, the platform changes with it.

It’s not just a dashboard. It’s the compliance command centre for a global trading floor — and the team behind it can answer “is every call captured?” with evidence, in real time.

Ready to turn the idea into an operating system?

Start a project